The Larva-24009 threat actor (aka HeptaX) continues phishing campaigns into 2026, using LNK files disguised as documents to deliver an obfuscated PowerShell backdoor. The attack chain involves downloading additional PowerShell scripts from C2 servers, establishing persistence via scheduled tasks, installing QuasarRAT and UltraVNC for remote control, and deploying NirSoft credential theft tools and a custom keylogger. A notable evolution is the use of the Telegram API for infection status reporting in the Notifier malware v2.1.
PowerShell backdoor
1 post
Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor